IP Library Granted Patent US 12695632
Granted Patent B2
US 12695632 · App. 18/843,099 · Granted Jul 28, 2026

Secure attestation of hardware device

Inventors: Niklas Lindskog (Lund, SE); Håkan Englund (Lund, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04L9/3278G06F21/57
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695632
App. No.
18/843,099
Granted
Jul 28, 2026
Kind
B2
Abstract

A device comprises a plurality of hardware, HW, modules including a first HW module comprising a Physically Unclonable Function, PUF, the first HW module or the plurality of HW modules being communicated with a requester. The device receives ( 1006 ), from the requester, a request to transmit an output to the requester. It activates ( 1008 ) the PUF, reads a response from the PUF, and adds the response to an output. The device transmits ( 1012 ) the output to the requester, and it receives ( 1002 ) one or more of a firmware, FW, component, a software, SW, component, or a bitstream, BS, component before receiving ( 1006 ) the request from the requester.

Claims (12)

1 . A method performed by a system comprising a plurality of hardware modules including a requester module and one or more further modules, each further module including a respective Physically Unclonable Function (PUF), the method comprising the requester module:

for each further module, obtaining a respective joint measurement based on a combination of a hardware output of the further module and a software measurement of the further module, the hardware output being unique to the further module and dependent upon a PUF response generated by the further module responsive to a request sent by the requester module, and the software measurement being a measurement of one or more of a firmware, software or bitstream component associated with the further module; and

using the respective joint measurements in at least one of a boot verification process and a remote attestation process, for verifying a combined hardware and software integrity of each respective further module, wherein verification of the combined hardware and software integrity of each respective further module depends upon comparing the respective joint measurement obtained for each respective further hardware module with a respective trusted joint measurement known for that further hardware module.

2 . The method of claim 1 , wherein the hardware output of each further module includes the PUF response and one or more of metadata and internal measurements of the further module.

3 . The method of claim 1 , wherein each further module outputs the respective joint measurement responsive to the request sent by the requester module, based on using a one-way function or hash having as inputs the respective hardware output and the respective software measurement.

4 . The method of claim 1 , wherein the requester module generates the joint measurement for each further module based receiving the respective hardware outputs from the one or more further modules, performing the respective software measurements for the one or more further modules, and computing the respective joint measurements according to a one-way function or hash.

5 . The method of claim 1 , wherein the one or more further modules includes at least first and second further modules.

6 . The method of claim 1 , wherein the requester module includes protected memory and wherein the method includes the requester module storing the respective joint measurements in the protected memory.

7 . The method of claim 6 , wherein the respective joint measurements are used in a boot verification process and wherein the method further comprises the requester module obtaining and storing the respective trusted joint measurements in a protected memory prior to performance of the boot verification process.

8 . A system comprising a plurality of hardware modules including a requester module and one or more further modules, each further module comprising a respective Physically Unclonable Function (PUF) and wherein the requester module comprises circuitry configured to:

for each further module, obtain a respective joint measurement based on a combination of a hardware output of the further module and a software measurement of the further module, the hardware output being unique to the further module and dependent upon a PUF response generated by the further module responsive to a request sent by the requester module, and the software measurement being a measurement of one or more of a firmware, a software, or a bitstream component associated with the further module; and

use the respective joint measurements in at least one of a boot verification process and a remote attestation process, for verifying a combined hardware and software integrity of each respective further module, wherein verification of the combined hardware and software integrity of each respective further module depends upon comparing the respective joint measurement obtained for each respective further hardware module with a respective trusted joint measurement known for that further hardware module.